CVE Database /
CVE-2026-16583
CVE
CVE-2026-16583 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-16583
|
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.8 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 3.0.8
|
3.0.8 |
2026-07-27 |
—
|
CVE-2026-16583
The Orbit Fox plugin's SVG upload functionality allows authorized users to upload malicious SVG files, which can contain executable JavaScript code. This code executes when the uploaded file is viewed on the affected website, enabling a stored cross-site scripting vulnerability. The issue affects versions of the plugin prior to 3.0.8.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings